[1.0.0] - 2026-08-25
Changed
-
Restore standalone interoperability targets for the compatibility module and
clean external consumer verification. -
Synchronize management-probe assertions with the owned readiness transition
so race-enabled verification cannot observe partial startup. -
Normalize reference-durability imports with the standalone CI formatter.
-
Align nested integration and benchmark modules with the current standalone
root archive checksum used by repository-local and CI verification. -
Make CodeQL resolve nested modules through that same current root archive.
-
Exclude intentional nested modules from root local-proxy archives so local,
bootstrap, CI, and public module checksums describe the same source
boundary. -
Track the pinned documentation-tool lockfile so clean CI checkouts install
the exact validated cspell dependency. -
Reconcile standalone dependency checksums against deterministic current
module archives so CI, local verification, and release consumers resolve
identical content. -
Harden standalone documentation validation with deterministic spelling and
link checks, package-specific documentation gates, and repository-local
contributor guidance.
Documentation
- Link the package README to the repository-wide Golib documentation portal.
Added
-
Add hardening simulations for stateful resilience lifecycles, concurrent
policy activity, sustained dependency outages, replica scaling, mixed
revisions, cold state, HPA feedback, and bounded fleet amplification. -
Bound runtime observation identities to 128 bytes and add structural guards
against implicit policy stacks, copied resilience algorithms, and global
policy registries. -
Add explicit component admission closure before cancellation, with
concurrency-safe repeated drain, rollback ordering, retained failures, and
integration hooks for stateful resilience policy lifecycle. -
Add resilience adoption evidence and guidance for named policy construction,
inbound and outbound placement, shared budgets and deadlines, readiness,
diagnostics, and Kubernetes replica and termination semantics. -
Add caller-owned runtime observation with identity-enriched logging and
bounded construction, lifecycle, component, task, probe, maintenance, and
business-request events. -
Add optional store-backed maintenance mode with
down,up, andstatus,
multi-replica storage adapters, readiness withdrawal, retry and refresh
headers, redirects, custom responses, and secret-cookie bypass. -
Add a canonical no-workspace clean-consumer gate that resolves and exercises
every documented public package through the repository source proxy without
areplacedirective. -
Allow typed service commands to declare bounded CLI options that are parsed
before their configuration loader receives the immutable invocation. -
Add the cohesive
Main,Execute, typed command, management probe, and
business HTTP construction path with correlation-owned request identity. -
Expose base and per-connection context hooks through
serverhttpoptions. -
Bound context-aware component startup with a configurable 30-second default.
-
Freeze the cohesive service-platform consumer inventory, public contracts,
dependency direction, compatibility plan, and numeric performance and
adoption budgets required before production API implementation. -
Add bounded Track, Postal, and Location adoption fixtures that preserve
explicit role dependencies and caller-owned correlation. -
Add an equivalent-behavior comparison harness for plain
net/http,
low-level and cohesiveservice, Chi, Gin, Echo, and Fiber/fasthttp. -
Add isolated process comparison evidence for startup, RSS, stripped binary
size, JSON-RPC and probe latency, throughput, and graceful shutdown. -
Extend equivalent-behavior performance evidence with Track ingestion and
JSON-RPC fan-out, Location lookup, and worker dispatch and supervision. -
Measure configured HTTP drain in a separately started process against the
declared graceful-shutdown deadline. -
Add a checksum-pinned disposable Kubernetes gate that proves canonical probe
and correlation behavior, readiness withdrawal, bounded termination,
business-only Service exposure, and probe-free one-shot migrations. -
Allow a selected typed plan to supply its validated management listener
configuration after application configuration loading.
Compatibility
- Added a pinned module export baseline so incompatible public API changes
fail the canonical repository gate.
Changed
-
Publish the module from its standalone
github.com/faustbrian/go-serviceidentity while preserving its documented API and behavior. -
Replace obsolete owned-module pseudo-version pins with the monorepo's local
v0.0.0source-proxy coordinates; release tooling continues to emit exact
v1.0.0dependency versions. -
Close component admission before root-runner, supervised-failure, and
startup-rollback cancellation so accepted work observes a stable drain
boundary. -
Remove unsupported exact-coverage and 2/2-mutation claims from the cataloged
non-production adoption harness while retaining its behavioral, race, and
frozen bootstrap-budget evidence. -
Supersede the earlier exact-
v1.0.0publication decision for this platform
goal: completion now ends at a verified commit tree, while version selection
and tag publication require separate maintainer authorization. -
Align compatibility, integration, security, testing, and release guidance
with the repository's Go 1.26.5 toolchain and sole owned CI workflow, and
state that platform completion does not select or publish av1.0.0tag. -
Reconcile the adoption and evidence summaries with the reviewed passing
Darwin and Linux/arm64 process-performance reports. -
Point every hosted service-gate mapping at the repository's sole owned CI
workflow. -
Rebaseline only the Darwin request, probe, startup, no-work shutdown, and
cohesive idle-RSS performance budgets from reviewed default-runtime captures
under the accepted sustained daily-work load. -
Default platform correlation uses bounded buffered UUIDv4 entropy to reduce
per-request system randomness overhead without changing identifier semantics. -
Migrate every runnable service example and the Kubernetes workload guide to
the cohesive command API, canonical management probes, and role-specific
initialization contract. -
Pin owned sibling modules to immutable source revisions so service resolves
from a clean external consumer without relying ongo.work. -
Move the lifecycle API from the pre-release
service/serviceimport into the
canonical rootservicepackage. -
Replace ambiguous
serverhttprequest-ID ownership with the typed
correlation/httpadapter. -
Join supervised tasks before closing their infrastructure components and
retain startup success while graceful cleanup runs. -
Supervise business HTTP so listener draining begins with readiness withdrawal
while dependency components remain available until in-flight work joins. -
Withdraw readiness immediately when the service lifetime context is
canceled. -
Escalate a second process signal by canceling remaining work while retaining
the original cleanup deadline and exit classification. -
Apply
Executesignal events from command construction through startup,
finite work, and cleanup while preserving the initiating typed cause. -
Keep an omitted caller-owned logger absent so the logging-disabled cohesive
path carries no platform logging initialization or binary cost. -
Refresh the hardening verdict with exact final-commit hosted evidence and
clarify that release publication is a separate maintainer action. -
Correct the platform release verdict to distinguish completed owning-module
adapters and consumer spikes from the remaining performance, aggregate
verification, and separately authorized publication gates. -
Record current input-fingerprinted local verification, including exact
coverage and mutation results plus retained NilAway and SBOM warnings. -
Record the sustained daily-work performance environment and preserve the
failed frozen absolute and lifecycle-relative budgets without waiting for an
otherwise idle host or weakening the thresholds. -
Refresh the release evidence matrix against the current service fingerprint
after analyzer maintenance and retain the current frozen-budget failures as
release blockers. -
Record passing Linux/arm64 portable and relative performance budgets plus
current complete framework and middleware-state comparison coverage while
retaining the failed Darwin absolute budgets as release blockers.
Added
- Add an isolated, pinned compatibility module and hosted gate that execute the
real configuration, logging, telemetry, authentication, authorization,
scheduler, and queue integration contracts without changing core dependencies. - Prove real sensitive configuration failures preserve typed causes, redact
rendered secrets, and prevent later component startup. - Refresh five-sample lifecycle, middleware, readiness, and integration
benchmark baselines after the concurrency hardening changes.
Fixed
- Record the reviewed disposition of every retained service and process-harness
NilAway advisory without representing the analyzer result as clean. - Enforce statistically significant paired evidence before classifying a
relative platform benchmark ratio as a regression, and distinguish the
corrected historical relative verdict from unchanged absolute failures. - Keep typed command options on the bounded CLI command-set path so cohesive
service binaries remain within the frozen absolute and relative size budgets. - Run compatibility dependency and vulnerability checks through the canonical
repository verifier so mutable localv0.0.0source-proxy checksums cannot
poison workspace verification. - Restore clean external installation from
mainby pinning the service
module's sibling requirements to reachable main pseudo-versions. - Resolve unreleased sibling modules from their main-branch pseudo-versions so
clean consumers can install the service module before tagged publication. - Apply the shared health-check concurrency limit before scheduling check work
so hostile probe traffic cannot create one waiting goroutine per check. - Treat supervised task results matching their canceled context or cancellation
cause as normal shutdown so context-aware runners do not create false errors. - Preserve public nil-context rejection tests under direct Staticcheck and
golangci-lint without weakening either analyzer.
Release integrity
- Source commit:
5ec87210a869a42f09cea1c368692c68e1e9a8cc - Exact-head CI: https://github.com/faustbrian/go-service/actions/runs/32918210102
- Release dry-run: urn:sha256:a19d3d180373cffd667ddb5411dd95152ee3da386807121b6fa04fb807921445
- Assets include a CycloneDX SBOM, SLSA v1 in-toto provenance, and SSH-signed checksums.
Verify the checksum attestation with:
ssh-keygen -Y verify -f ALLOWED_SIGNERS -I brian@cline.sh -n golib-release -s SHA256SUMS.sig < SHA256SUMS